Privacy Policy

Last updated: March 2026

1. Who We Are

Pikaboo Enterprises ("we", "us", "our") operates the Pikaboo video calling platform. We provide private, encrypted video calling services to charities and organisations ("Clients") who deploy instances for their teams.

2. What This Policy Covers

This policy explains what personal data we collect, why we collect it, how we store it, and your rights. It applies to all users ("you") of any Pikaboo instance hosted on our infrastructure.

3. Data We Collect

3.1 Data We Store

DataPurposeStorage LocationRetention
UsernameIdentify authorised usersUpstash Redis (EU)Until removed by admin
TOTP secretAuthenticator-based loginUpstash Redis (EU)Until admin resets or removes user
Session tokenMaintain login stateUpstash Redis (EU)Auto-expires after 30 minutes
Last TOTP time stepPrevent code replay attacksUpstash Redis (EU)Overwritten on each login

3.2 Data We Process but Do Not Store

DataPurposeNotes
IP addressRate limiting (anti-abuse)Held in server memory only, never written to disk or database. Cleared when the rate limit window resets (60 seconds)
TURN relay trafficRelay encrypted media when direct connection failsHandled by Cloudflare. Encrypted packets pass through but cannot be decrypted by us or Cloudflare
File transfer metadataCoordinate peer-to-peer file transferFile name, size, and SHA-256 hash exchanged between peers via data channel. Never sent to or stored on our server. Discarded when session ends

3.3 Data We Never Collect

4. How Calls Work - Why We Can't Access Your Data

Pikaboo uses WebRTC (Web Real-Time Communication) for all video and audio calls:

In short: we cannot see, hear, or record your calls, messages, captions, or file transfers - even if compelled to by law - because the data never reaches us.

5. Lawful Basis for Processing (GDPR)

DataLawful BasisExplanation
Username, TOTP secretLegitimate interest (Article 6(1)(f))Necessary to authenticate users and prevent unauthorised access
Session tokenLegitimate interest (Article 6(1)(f))Necessary to maintain login state for the duration of a session
IP address (in memory)Legitimate interest (Article 6(1)(f))Necessary to prevent brute-force attacks and abuse

We do not rely on consent as our lawful basis because the processing is minimal and strictly necessary for the service to function securely.

6. Where Your Data Is Stored

ServiceRoleLocationProvider Privacy
Hetzner CloudVPS hosting (server, signaling)Falkenstein, Germany (EU)hetzner.com
UpstashRedis database (auth data)EU regionupstash.com
CloudflareDNS, TLS certificates, TURN relayGlobal (anycast)cloudflare.com

All stored personal data (usernames, TOTP secrets, sessions) resides in the EU.

7. Data Sharing

We do not sell, trade, or share personal data with third parties for marketing or any other purpose.

Data is only processed by our sub-processors (Hetzner, Upstash, Cloudflare) as strictly necessary to operate the service.

8. Data Retention

DataRetention Period
UsernameUntil removed by a tenant admin
TOTP secretUntil reset or user removed by admin
Session tokenAuto-deleted after 30 minutes
IP address (memory only)Cleared after 60 seconds

We do not retain any data beyond what is listed above. There are no backups of call content because no call content is ever stored.

9. Your Rights (GDPR)

Under the UK GDPR and EU GDPR, you have the right to:

To exercise any of these rights, contact privacy@pikaboo.app. We will respond within 30 days.

For username/TOTP deletion, your tenant admin can also remove your account immediately via the admin panel.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe your data has been mishandled.

10. Children

Pikaboo is provided to organisations for use by their authorised staff and beneficiaries. We do not knowingly collect data from children under 13. If you believe a child's data has been processed, contact us at privacy@pikaboo.app.

11. Changes to This Policy

We may update this policy from time to time. Changes will be reflected in the "Last updated" date at the top. For significant changes, we will notify our Clients who will inform their users.

12. Contact

For any questions about this policy or your personal data:

Email: privacy@pikaboo.app